Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: Vulnerability in sourceforge.net
From: Anders B Jansson <hdw () kallisti se>
Date: Fri, 23 Jul 2004 00:50:49 +0200

nobody:*:32767:32767:Unprivileged user:/nonexistent:/sbin/nologin

Todd Towles wrote:
Does OpenBSD do that?

-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of Gregory A.
Sent: Thursday, July 22, 2004 3:31 PM
To: full-disclosure () lists netsys com
Subject: Re: [Full-disclosure] Vulnerability in sourceforge.net

Really...FreeBSD comes with user nobody set to /sbin/nologin out of the
box. Maybe they should have chosen a better host OS?


On or about 2004.07.22 07:49:53 +0000, Todd Towles
(toddtowles () brookshires com) said:

Sounds like they should have configured that page a bit different...made


run under a little less access...or said I say..it is a mis-configuration.

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]